Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 335

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
More than half of Americans come up as much as $250 short each month — here's how to find that money
Situational Awareness hedge fund meltdown was a warning shot for leveraged markets, BofA CEO says
SpaceX gives Nvidia a much-needed boost. Plus, Cramer on an 'undervalued' stock
Salad and Go files for Chapter 11 bankruptcy after cyclospora fears worsened its challenges
Another "identify this title from my youth" question
Silo: Memory Show Only
Follow-up - anti-depressants and (male) sex, difficulty climaxing
SpaceX's earnings are not helping its stock, but Nvidia is getting a boost
Movie: The Temptation of St. Tony
Ted Lasso: Home